Find Your Next Job
Senior Product Security Engineer
Posted on Dec. 9, 2024
- Dublin, Ireland
- 0 - 0 USD (yearly)
- Full Time
Define, review and validate application security requirements with Product Development teams, ensuring alignment with security standards.
- Integrate security features for authentication and authorization, using technologies such as OIDC, SAML SSO and JAAS.
- Implement controls to address vulnerabilities, including OWASP Top 10 risks like CSRF, XSS and XXE.
- Collaborate with development teams to validate security fixes and promote best practices.
- Review codebases for vulnerabilities and assess issues flagged by security scanning tools.
- Serve as a primary responder to security issues identified by the Product Security Response Team (PSRT), coordinating efforts for timely remediation.
- Interpret and communicate PSRT advisory reports to development teams, providing guidance to address identified vulnerabilities.
- Conduct Open Source Software (OSS) vulnerability assessments to maintain secure software dependencies.
- Perform SAST and DAST testing with tools like SonarQube and Burp Suite Pro to proactively identify security risks.
- Configure and manage security scanning tools to meet project needs.
- Conduct internal penetration tests and support external pen testers in assessments of on-premises and Kubernetes-based applications.
- Document, assess and address security risks and any deviations from security standards.
- Serve as a primary contact for security incidents, handling security-related customer cases and incident responses.
- Coordinate with the CISO team for security sign-offs on product releases.
- Support ISO 27001 and other certification efforts to ensure compliance with industry standards.
Basic Qualifications:
Security Expertise: Deep knowledge of security vulnerabilities, risks, and mitigation techniques, with experience in vulnerability management frameworks such as CVE and CVSS.
- Technical Skills:
- Proficiency in SAST, DAST and IAST security scanning tools (e.g., SonarQube, Burp Suite, etc.) and vulnerability scanning tools like JFrog Xray.
- Expertise in integrating and managing security tools within CI/CD pipelines using GitHub Advanced Security and Jenkins.
- Strong skills in Java, JavaScript, XML, and YAML for application security, configuration management, and security automation.
- Solid understanding of Kubernetes security and cloud environment configurations.
- Understanding of security requirements for deployments on application servers, including IBM WebSphere Liberty, IBM WebSphere Application Server and Oracle WebLogic Server.
- Proficiency in cryptographic algorithms, including encryption, hashing, digital signatures, and secret key management ensuring secure data transmission and storage.
- Risk Management Knowledge: Experience managing security risks and ensuring compliance within regulated industries, ideally in HHS.
- Collaboration and Communication Skills: Proven ability to work cross-functionally and communicate security requirements with both technical and non-technical stakeholders.
- Problem-Solving Skills: Strong analytical abilities to identify, evaluate, and resolve complex security issues.
Tailor Your Resume for this Job
Share with Friends!
Similar Jobs
Amazon.com
Senior Solutions Architect, Global Financial Services
8+ years of specific technology domain areas (e.g. software development, cloud computing, systems …
Full Time | Singapore, Singapore
Apply 1 day, 19 hours ago
Visa
Senior Software Engineer
Company Description Visa is a world leader in payments and technology, with over 259 billion paymen…
Full Time | Singapore, Singapore
Apply 1 day, 22 hours ago
Fujitsu
Soc Analyst - Auckland Or Wellington
About the job SOC Analyst - Auckland or Wellington We are Fujitsu We use technology to make happie…
Full Time | Auckland city, New Zealand
Apply 1 day, 22 hours ago
BNP Paribas
Itg Sccm Engineer Bnp Paribas (#Mitp)
GROUP BNP PARIBAS BNP Paribas Group is the top bank in the European Union and a major internationa…
Full Time | Madrid, Spain
Apply 2 days, 3 hours ago
Amazon.com
Eu Health & Safety Launch Program Manager , Eu Design, Construction And Startup (Dcs) Team
A Bachelor degree or equivalent level of qualification in line with the European Qualifications Fr…
Full Time | Luxembourg, Luxembourg
Apply 2 days, 7 hours ago
Channel Mechanics
Director Of Azure Cloud Services
Job Summary The Director of Azure Cloud Services is a strategic leadership role responsible for ov…
Full Time | Galway, Ireland
Apply 2 days, 7 hours ago
Rockwell Automation
Senior Firmware Engineer
Rockwell Automation is a global technology leader focused on helping the world’s manufacturer…
Full Time | Hougang, Singapore
Apply 2 days, 19 hours ago
Lightspeed
Intermediate Software Developer (Full Stack)
Hi there! Thanks for stopping by Are you actively looking for a new opportunity? Or just checki…
Full Time | Auckland city, New Zealand
Apply 2 days, 22 hours ago